Thailand PDPA and Crypto Travel Rule: What Exchanges Must Do with Your Data in 2026

Thailand SEC crypto Travel Rule comment period closes July 10, 2026. Combined with Thailand PDPA data protection law, exchanges face new obligations on how they collect, store, and transmit your personal data.
Thailand PDPA and Crypto Travel Rule: What Exchanges Must Do with Your Data in 2026

Two regulatory timelines converged in early July 2026. The Thailand SEC’s public comment period on the crypto Travel Rule closes July 10. And Thailand’s Personal Data Protection Act has been in enforcement since mid-2022. The Travel Rule requires digital asset exchanges to collect and transmit originator and beneficiary information with every crypto transfer. The PDPA governs how that personal data can be collected, stored, shared, and deleted. The intersection creates specific obligations — and specific liability — that licensed exchanges and their customers both need to understand.

What the Travel Rule Requires

The Financial Action Task Force Travel Rule requires that when digital assets move between Virtual Asset Service Providers, identifying information must travel with the funds. Thailand’s SEC draft Travel Rule requires exchanges to collect:

  • Originator name, account number, and address for outgoing transfers above a threshold
  • Beneficiary name and account number for incoming transfers
  • Ownership verification for transfers to or from self-hosted (personal) wallets

For licensed Thai exchanges — Bitkub, Gulf Binance, Satang Pro — this means building data collection systems at the transfer level. It is a significant compliance infrastructure investment that also changes the user experience for withdrawal and deposit flows.

Where the PDPA Intersects

Thailand’s PDPA requires that personal data collected from customers has a legal basis (contract, legal obligation, legitimate interest, or consent), is collected only to the extent necessary, is held no longer than required for its purpose, and is protected against unauthorised access and disclosure. The Travel Rule creates a “legal obligation” basis for collecting transfer data. But the PDPA imposes conditions on how that data is then stored, who can access it, and when it must be deleted. An exchange that retains Travel Rule data indefinitely — or shares it with third parties beyond the receiving licensed exchange — may be Travel Rule compliant but PDPA non-compliant simultaneously.

The Self-Hosted Wallet Problem

The most contested element of the Travel Rule is the requirement to verify ownership or control of a self-hosted wallet. When a Bitkub user sends funds from their exchange account to their personal MetaMask wallet, Bitkub must verify that the MetaMask address belongs to the account holder. The methods for doing this — cryptographic signed message verification, small test transfer and confirm, or explicit user attestation — all involve collecting additional personal data. The PDPA applies to all of it. Exchanges that implement ownership verification hastily, without proper data minimisation and retention policies, face a PDPA enforcement risk layered on top of their Travel Rule compliance effort.

What This Means for Thai Crypto Users

The practical impact on retail users is direct. Expect more steps when withdrawing to self-hosted wallets — exchanges may ask you to sign a message from your wallet address to prove ownership. Your transfer data (originator and beneficiary information) will be shared with the receiving licensed exchange when both parties are licensed Thai VASPs. You have PDPA rights: you can request access to the personal data the exchange holds about your transfer history, and you can request deletion when retention periods expire. Exchanges are required under the PDPA to respond to these subject access requests within 30 days.

The Unlicensed Platform Gap

Travel Rule obligations apply only to licensed VASPs. When a Thai user transfers crypto to an unlicensed overseas exchange — now blocked under Thailand’s extraterritorial enforcement framework but still accessible via VPN — the Travel Rule information flow breaks. The licensed Thai exchange cannot collect counterparty information from an unlicensed platform. This compliance gap gives regulators another justification for stricter enforcement against unlicensed platforms and, potentially, against Thai users who route funds to them.

What to Watch

July 10 is the comment deadline. Final Travel Rule regulations are expected later in 2026, with a likely 6-12 month implementation runway for exchanges to build compliant systems. Watch for the SEC’s final framework, which will specify the monetary threshold triggering Travel Rule obligations, specific data retention periods (the direct PDPA intersection), and the technical standard required for self-hosted wallet verification. The enforcement calendar is also relevant: the SEC filed criminal complaints against licensed brokers as recently as February 2026, demonstrating its willingness to use the full range of enforcement tools available.

BrokerTH